[Oct 25, 2021] NSE6_FWB-6.1 PDF Recently Updated Questions Dumps to Improve Exam Score
NSE6_FWB-6.1 Dumps Full Questions with Free PDF Questions to Pass
NEW QUESTION 13
A client is trying to start a session from a page that would normally be accessible only after the client has logged in.
When a start page rule detects the invalid session access, what can FortiWeb do? (Choose three.)
- A. Redirect the client to the login page
- B. Reply with a 403 Forbidden HTTP error
- C. Display an access policy message, then allow the client to continue
- D. Prompt the client to authenticate
- E. Allow the page access, but log the violation
Answer: A,B,E
NEW QUESTION 14
In which scenario might you want to use the compression feature on FortiWeb?
- A. When you are offering a music streaming service
- B. Never, since most traffic today is already highly compressed
- C. When you want to reduce buffering of video streams
- D. When you are serving many corporate road warriors using 4G tablets and phones
Answer: B
Explanation:
FortiWeb might expend resources compressing responses that have already been compressed by the server.
NEW QUESTION 15
Which two statements about running a vulnerability scan are true? (Choose two.)
- A. You should run the vulnerability scan on a live website to get accurate results.
- B. You should run the vulnerability scan during a maintenance window.
- C. Vulnerability scanning increases the load on FortiWeb, so it should be avoided.
- D. You should run the vulnerability scan in a test environment.
Answer: B,D
Explanation:
Should the Vulnerability Scanner allow it, SVMS will set the scan schedule (or schedules) to run in a maintenance window. SVMS will advise Client of the scanner's ability to complete the scan(s) within the maintenance window.
Vulnerabilities on live web sites. Instead, duplicate the web site and its database in a test environment.
Reference:
https://help.fortinet.com/fweb/552/Content/FortiWeb/fortiweb-admin/vulnerability_scans.htm
NEW QUESTION 16
What must you do with your FortiWeb logs to ensure PCI DSS compliance?
- A. Compress them into a .zip file format
- B. Erase them every two weeks
- C. Store in an off-site location
- D. Enable masking of sensitive data
Answer: D
NEW QUESTION 17
True transparent proxy mode is best suited for use in which type of environment?
- A. New networks where infrastructure is not yet defined
- B. Flexible environments where you can easily change the IP addressing scheme
- C. Environments where you cannot change the IP addressing scheme
- D. Small office to home office environments
Answer: C
Explanation:
Does not require changes to the IP address scheme of the network. Requests are destined for a web server and not the FortiWeb appliance. This operation mode supports the same feature set as True Transparent Proxy mode.
NEW QUESTION 18
What role does FortiWeb play in ensuring PCI DSS compliance?
- A. It provides the ability to securely process cash transactions.
- B. It provides the WAF required by PCI.
- C. It provides the required SQL server protection.
- D. It provides credit card processing capabilities.
Answer: D
Explanation:
FortiWeb protects against attacks that lead to sensitive data exposure such as SQL Injection and other injection types. Additionally, FortiWeb inspects all web server outgoing traffic for sensitive data such as Social Security numbers, credit card numbers and other predefined or custom based sensitive data.
NEW QUESTION 19
What key factor must be considered when setting brute force rate limiting and blocking?
- A. Multiple clients from geographically diverse locations
- B. A single client contacting multiple resources
- C. Multiple clients connecting to multiple resources
- D. Multiple clients sharing a single Internet connection
Answer: C
NEW QUESTION 20
How does FortiWeb protect against defacement attacks?
- A. It keeps a live duplicate of the database.
- B. It keeps a complete backup of all files and the database.
- C. It keeps full copies of all files and directories.
- D. It keeps hashes of files and periodically compares them to the server.
Answer: D
Explanation:
The anti-defacement feature examines a web site's files for changes at specified time intervals. If it detects a change that could indicate a defacement attack, the FortiWeb appliance can notify you and quickly react by automatically restoring the web site contents to the previous backup.
NEW QUESTION 21
When viewing the attack logs on FortiWeb, which client IP address is shown when you are using XFF header rules?
- A. FortiWeb IP
- B. FortiGate public IP
- C. Client real IP
- D. FortiGate local IP
Answer: C
Explanation:
When an XFF header reaches Alteon from a client, Alteon removes all the content from the header and injects the client IP address. Alteon then forwards the header to the server.
NEW QUESTION 22
Refer to the exhibit.
FortiADC is applying SNAT to all inbound traffic going to the servers. When an attack occurs, FortiWeb blocks traffic based on the 192.0.2.1 source IP address, which belongs to FortiADC. The setup is breaking all connectivity and genuine clients are not able to access the servers.
What must the administrator do to avoid this problem? (Choose two.)
- A. Enable the Add X-Forwarded-For setting on FortiWeb.
- B. No Special configuration is required; connectivity will be re-established after the set timeout.
- C. Enable the Use X-Forwarded-For setting on FortiWeb.
- D. Place FortiWeb in front of FortiADC.
Answer: A,C
Explanation:
Configure your load balancer to insert or append to an X-Forwarded-For:, X-Real-IP:, or other HTTP X-header. Also configure FortiWeb to find the original attacker's or client's IP address in that HTTP header
NEW QUESTION 23
Refer to the exhibit.
FortiWeb is configured to block traffic from Japan to your web application server. However, in the logs, the administrator is seeing traffic allowed from one particular IP address which is geo-located in Japan.
What can the administrator do to solve this problem? (Choose two.)
- A. If the IP address is configured as an IP reputation exception, remove it.
- B. If the IP address is configured as a geo reputation exception, remove it.
- C. Manually update the geo-location IP addresses for Japan.
- D. Configure the IP address as a blacklisted IP address.
Answer: C,D
Explanation:
IP reputation leverages many techniques for accurate, early, and frequently updated identification of compromised and malicious clients so you can block attackers before they target your servers.
IP blacklisting is a method used to filter out illegitimate or malicious IP addresses from accessing your networks. Blacklists are lists containing ranges of or individual IP addresses that you want to block.
Reference:
https://www.imperva.com/learn/application-security/ip-blacklist/
NEW QUESTION 24
When is it possible to use a self-signed certificate, rather than one purchased from a commercial certificate authority?
- A. If you are an enterprise whose computers all trust your active directory or other CA server
- B. If you are an enterprise whose resources do not need security
- C. If you are a small business or home office
- D. If you are an enterprise whose employees use only mobile devices
Answer: B
Explanation:
This can include SSL/TLS certificates, code signing certificates, and S/MIME certificates. The reason why they're considered different from traditional certificate-authority signed certificates is that they're created, issued, and signed by the company or developer who is responsible for the website or software being signed. This is why self-signed certificates are considered unsafe for public-facing websites and applications.
NEW QUESTION 25
......
100% Updated Fortinet NSE6_FWB-6.1 Enterprise PDF Dumps: https://www.practicematerial.com/NSE6_FWB-6.1-exam-materials.html

